CVE-2023-6863: High severity thunderbird vulnerability
Last updated 24 July 2024
Other sources
The ShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor.
External Reference: https://www.mozilla.org/en-US/security/advisories/mfsa2023-54/#CVE-2023-6863
— Red Hat
The ShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
— Launchpad
The ShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virtual destructor.
— Mozilla
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2023-6863?
CVE-2023-6863 is considered a moderate severity vulnerability due to its potential to cause undefined behavior.
How do I fix CVE-2023-6863?
To fix CVE-2023-6863, users should update to Firefox ESR version 115.6 or later, Thunderbird version 115.6 or later, or apply the appropriate package updates for Debian systems.
What software is affected by CVE-2023-6863?
CVE-2023-6863 affects Mozilla Firefox ESR versions prior to 115.6, Thunderbird versions prior to 115.6, and specific versions of the Firefox and Thunderbird packages on Debian.
Is CVE-2023-6863 being actively exploited?
As of now, there is no public information indicating that CVE-2023-6863 is actively being exploited in the wild.
What are the potential impacts of CVE-2023-6863?
The potential impacts of CVE-2023-6863 include application crashes and unstable behavior due to undefined behavior in the affected software.